Vulnerabilities/

wangEditor was discovered to contain a cross-site scripting (XSS) vulnerability via the image upload function

Severity:
Medium

Description

There is a cross-site scripting (XSS) issue in wangEditor via the image upload function in version 4.7.11. This issue has been fixed in version 4.7.12.

Recommendation

Update the @wangeditor/editor package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@wangeditor/editor
Anything's wrong? Let us know Last updated on June 11, 2026